Home Malware Programs Worms Looksky.d

Looksky.d

Posted: March 28, 2006

Looksky.d is a dangerous Internet worm, which spreads by e-mail. It arrives in infected executable files attached to bogus e-mail messages.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 attrib.ini
    2 main_23_c.exe
    3 msvcrl.dll
    4 sachostb.exe
    5 sachostc.exe
    6 sachostp.exe
    7 sachosts.exe
    8 sachostw.exe
    9 sachostx.exe
    10 tmx[X].exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunhotsrv=%Windir%sachostx.exe
Loading...